CERT-In Vulnerability Note
CIVN-2013-0220
Multiple Vulnerabilities in Microsoft Exchange Server
Original Issue Date:December 11, 2013
Severity Rating: HIGH
Systems Affected
- Microsoft Exchange Server 2010 SP2
- Microsoft Exchange Server 2007 SP3
- Microsoft Exchange Server 2010 SP3
- Microsoft Exchange Server 2013 Cumulative Update 2
- Microsoft Exchange Server 2013 Cumulative Update 3
Component Affected
- Oracle Outside In Technology versions 8.4.0 and 8.4.1
Overview
Multiple remote code execution vulnerabilities have been reported in Microsoft Windows Exchange Server and share point server which could allow a remote attacker to execute arbitrary code, or perform cross-site scripting (XSS) attacks.
Description
1. Multiple Vulnerabilities Oracle Outside In
(
CVE-2013-5763
CVE-2013-5791
)
These vulnerabilities exist in the Oracle Outside In library in WebReady Document Viewing feature of Microsoft Windows Exchange server. An attacker could exploit these vulnerabilities by enticing a user to open a specially crafted email message in Outlook Web Access (OWA), leading to arbitrary code execution in Local system Service account.
2. MAC Disabled Vulnerability
(
CVE-2013-1330
)
This vulnerability exists while handling unassigned workflows due to improper validation of user supplied input by the affected software. An unauthenticated, remote attacker could exploit this issue to execute arbitrary code with the privileges of the Outlook Web Access (OWA) service account. The targeted system could be completely compromised if the user holds elevated privileges.
3. OWA XSS Vulnerability
(
CVE-2013-5072
)
This vulnerability exists in the Outlook Web Access (OWA) component of Microsoft Exchange while processing crafted URLs due to improper validation and sanitation of user-supplied input. An unauthenticated, remote attacker could exploit this issue by enticing a user to follow malicious link to perform cross-site scripting (XSS) attacks.
Workaround
- Disable Data Loss Prevention (Exchange Server 2013 only)
- Disable WebReady document view (Exchange Server 2007, Exchange Server 2010, and Exchange Server 2013)
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS13-105
Vendor Information
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms13-105
References
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms13-105
Oracle
http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=31478
http://tools.cisco.com/security/center/viewAlert.x?alertId=31316
http://tools.cisco.com/security/center/viewAlert.x?alertId=30551
http://tools.cisco.com/security/center/viewAlert.x?alertId=31974
CVE Name
CVE-2013-5763
CVE-2013-5791
CVE-2013-1330
CVE-2013-5072
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|